Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-45968

Опубликовано: 18 мар. 2022
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Высокий

Описание

An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jivesoftware:jive:-:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:pascom:cloud_phone_system:*:*:*:*:*:*:*:*
Версия до 7.19 (включая)

EPSS

Процентиль: 99%
0.70707
Высокий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.5
github
почти 4 года назад

An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394.

EPSS

Процентиль: 99%
0.70707
Высокий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-918